improvements: address feedback, feature docs and cert validation with dns rebinding handling

This commit is contained in:
Scott Wilson
2025-04-03 21:17:04 -07:00
parent 577c81be65
commit 715441908b
24 changed files with 708 additions and 306 deletions
+126
View File
@@ -0,0 +1,126 @@
---
title: "Microsoft SQL Server Connection"
description: "Learn how to configure a Microsoft SQL Server Connection for Infisical."
---
Infisical supports connecting to Microsoft SQL Server using database principals.
## Configure a Microsoft SQL Server Principal for Infisical
<Steps>
<Step title="Create a Principal">
Infisical recommends creating a designated server login and database user in your Microsoft SQL Server database for your connection.
```SQL
-- create server-level login
CREATE LOGIN infisical_login WITH PASSWORD = 'my-password';
-- create database-level user with login from above
USE my_database;
CREATE USER infisical_user FOR LOGIN infisical_login;
GRANT CONNECT TO infisical_user;
-- If you intend to use Platform Managed Credentials (see below)
GRANT ALTER ANY LOGIN TO infisical_login;
```
</Step>
<Step title="Grant Relevant Permissions">
Depending on how you intend to use your Microsoft SQL Server connection, you'll need to grant one or more of the following permissions.
<Tip>
To learn more about Microsoft SQL Server's permission system, please visit their [documentation](https://learn.microsoft.com/en-us/sql/t-sql/statements/grant-transact-sql?view=sql-server-ver16).
</Tip>
<Tabs>
<Tab title="Secret Rotation">
For Secret Rotations, your Infisical user will require the ability to alter other logins' passwords:
```SQL
GRANT ALTER ANY LOGIN TO infisical_login;
```
</Tab>
</Tabs>
</Step>
<Step title="Get Connection Details">
You'll need the following information to create your Microsoft SQL Server connection:
- `host` - The hostname or IP address of your Microsoft SQL Server server
- `port` - The port number your Microsoft SQL Server server is listening on (default: 1433)
- `database` - The name of the specific database you want to connect to
- `username` - The username of the login created in the steps above
- `password` - The password of the login created in the steps above
- `sslCertificate` (optional) - The SSL certificate required for connection (if configured)
</Step>
</Steps>
## Create Connection in Infisical
<Tabs>
<Tab title="Infisical UI">
1. Navigate to the App Connections tab on the Organization Settings page.
![App Connections Tab](/images/app-connections/general/add-connection.png)
2. Select the **Microsoft SQL Server Connection** option.
![Select Microsoft SQL Server Connection](/images/app-connections/mssql/select-mssql-connection.png)
3. Select the **Username & Password** method option and provide the details obtained from the previous section and press **Connect to Microsoft SQL Server**.
<Note>
Optionally, if you'd like Infisical to manage the credentials of this connection, you can enable the Platform Managed Credentials option.
If enabled, Infisical will update the password of the connection on creation to prevent external access to this database role.
</Note>
![Create Microsoft SQL Server Connection](/images/app-connections/mssql/create-username-and-password-method.png)
4. Your **Microsoft SQL Server Connection** is now available for use.
![Assume Role Microsoft SQL Server Connection](/images/app-connections/mssql/username-and-password-connection.png)
</Tab>
<Tab title="API">
To create a Microsoft SQL Server Connection, make an API request to the [Create PostreSQL
Connection](/api-reference/endpoints/app-connections/mssql/create) API endpoint.
<Note>
Optionally, if you'd like Infisical to manage the credentials of this connection, you can set the `isPlatformManagedCredentials` option to `true`.
If enabled, Infisical will update the password of the connection on creation to prevent external access to this database role.
</Note>
### Sample request
```bash Request
curl --request POST \
--url https://app.infisical.com/api/v1/app-connections/mssql \
--header 'Content-Type: application/json' \
--data '{
"name": "my-mssql-connection",
"method": "username-and-password",
"isPlatformManagedCredentials": true,
"credentials": {
"host": "123.4.5.6",
"port": 1433,
"database": "default",
"username": "infisical_login",
"password": "my-password",
},
}'
```
### Sample response
```bash Response
{
"appConnection": {
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"name": "my-pg-connection",
"version": 1,
"orgId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"createdAt": "2023-11-07T05:31:56Z",
"updatedAt": "2023-11-07T05:31:56Z",
"app": "mssql",
"method": "username-and-password",
"isPlatformManagedCredentials": true,
"credentials": {
"host": "123.4.5.6",
"port": 1433,
"database": "default",
"username": "infisical_login"
}
}
}
```
</Tab>
</Tabs>
@@ -74,4 +74,9 @@ in the UI or by passing the associated `connectionId` when generating resources
<Note>
Infisical is continuously expanding its third-party application support. If your desired application isn't listed,
you can still use previous methods of connecting to it such as our Native Integrations.
</Note>
</Note>
## Platform Managed Credentials
Some App Connections support the ability to have their credentials managed by Infisical. By enabling this option,
Infisical will modify the credentials to prevent external use of the configured access entity.
@@ -0,0 +1,119 @@
---
title: "PostgreSQL Connection"
description: "Learn how to configure a PostgreSQL Connection for Infisical."
---
Infisical supports connecting to PostgreSQL using a database role.
## Configure a PostgreSQL Role for Infisical
<Steps>
<Step title="Create a Role">
Infisical recommends creating a designated role in your PostgreSQL database for your connection.
```SQL
-- create user role
CREATE ROLE infisical_role WITH LOGIN PASSWORD 'my-password'
-- grant login access to the specified database
GRANT CONNECT ON DATABASE my_database TO infisical_role;
```
</Step>
<Step title="Grant Relevant Permissions">
Depending on how you intend to use your PostgreSQL connection, you'll need to grant one or more of the following permissions.
<Tip>
To learn more about PostgreSQL's permission system, please visit their [documentation](https://www.postgresql.org/docs/current/sql-grant.html).
</Tip>
<Tabs>
<Tab title="Secret Rotation">
For Secret Rotations, your Infisical user will require the ability to alter other users' passwords:
```SQL
ALTER ROLE infisical_role WITH CREATEROLE;
```
</Tab>
</Tabs>
</Step>
<Step title="Get Connection Details">
You'll need the following information to create your PostgreSQL connection:
- `host` - The hostname or IP address of your PostgreSQL server
- `port` - The port number your PostgreSQL server is listening on (default: 5432)
- `database` - The name of the specific database you want to connect to
- `username` - The role name of the login created in the steps above
- `password` - The role password of the login created in the steps above
- `sslCertificate` (optional) - The SSL certificate required for connection (if configured)
</Step>
</Steps>
## Create Connection in Infisical
<Tabs>
<Tab title="Infisical UI">
1. Navigate to the App Connections tab on the Organization Settings page.
![App Connections Tab](/images/app-connections/general/add-connection.png)
2. Select the **PostgreSQL Connection** option.
![Select PostgreSQL Connection](/images/app-connections/postgres/select-postgres-connection.png)
3. Select the **Username & Password** method option and provide the details obtained from the previous section and press **Connect to PostgreSQL**.
<Note>
Optionally, if you'd like Infisical to manage the credentials of this connection, you can enable the Platform Managed Credentials option.
If enabled, Infisical will update the password of the connection on creation to prevent external access to this database role.
</Note>
![Create PostgreSQL Connection](/images/app-connections/postgres/create-username-and-password-method.png)
4. Your **PostgreSQL Connection** is now available for use.
![Assume Role PostgreSQL Connection](/images/app-connections/postgres/username-and-password-connection.png)
</Tab>
<Tab title="API">
To create a PostgreSQL Connection, make an API request to the [Create PostgreSQL
Connection](/api-reference/endpoints/app-connections/postgres/create) API endpoint.
<Note>
Optionally, if you'd like Infisical to manage the credentials of this connection, you can set the `isPlatformManagedCredentials` option to `true`.
If enabled, Infisical will update the password of the connection on creation to prevent external access to this database role.
</Note>
### Sample request
```bash Request
curl --request POST \
--url https://app.infisical.com/api/v1/app-connections/postgres \
--header 'Content-Type: application/json' \
--data '{
"name": "my-pg-connection",
"method": "username-and-password",
"isPlatformManagedCredentials": true,
"credentials": {
"host": "123.4.5.6",
"port": 5432,
"database": "default",
"username": "infisical_role",
"password": "my-password",
},
}'
```
### Sample response
```bash Response
{
"appConnection": {
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"name": "my-pg-connection",
"version": 1,
"orgId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"createdAt": "2023-11-07T05:31:56Z",
"updatedAt": "2023-11-07T05:31:56Z",
"app": "postgres",
"method": "username-and-password",
"isPlatformManagedCredentials": true,
"credentials": {
"host": "123.4.5.6",
"port": 5432,
"database": "default",
"username": "infisical_role"
}
}
}
```
</Tab>
</Tabs>